Cybersecurity events are documented based on the established criteria
Context and Guidance: Anything that is an event according to the criteria defined in RESPONSE-1b should be documented in a consistent manner. The organisation should decide what details about events should be documented to enable, for example, (1) decisions about declaring events to be incidents, (2) collection of data for any event metrics the organisation might be tracking, and (3) correlation of event information, if the organisation is doing that.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RESPONSE-1a, RESPONSE-1b, RESPONSE-1c, RESPONSE-1f.